Pre-Winter Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

IAPP AIGP Dumps

Page: 1 / 22
Total 215 questions

Artificial Intelligence Governance Professional Questions and Answers

Question 1

CASE STUDY

Please use the following answer the next question:

Good Values Corporation (GVC) is a U.S. educational services provider that employs teachers to create and deliver enrichment courses for high school students. GVC has learned that many of its teacher employees are using generative Al to create the enrichment courses, and that many of the students are using generative Al to complete their assignments.

In particular, GVC has learned that the teachers they employ used open source large language models (“LLM”) to develop an online tool that customizes study questions for individual students. GVC has also discovered that an art teacher has expressly incorporated the use of generative Al into the curriculum to enable students to use prompts to create digital art.

GVC has started to investigate these practices and develop a process to monitor any use of generative Al, including by teachers and students, going forward.

What is the best reason for GVC to offer students the choice to utilize generative Al in limited, defined circumstances?

Options:

A.

To enable students to learn how to manage their time.

B.

To enable students to learn about performing research.

C.

To enable students to learn about practical applications of Al.

D.

To enable students to learn how to use Al as a supportive educational tool.

Question 2

During the development of semi-autonomous vehicles, various failures occurred as a result of the sensors misinterpreting environmental surroundings, such as sunlight.

These failures are an example of?

Options:

A.

Hallucination.

B.

Brittleness.

C.

Uncertainty.

D.

Forgetting.

Question 3

You are part of your organization’s ML engineering team and notice that the accuracy of a model that was recently deployed into production is deteriorating.

What is the best first step address this?

Options:

A.

Replace the model with a previous version.

B.

Conduct champion/challenger testing.

C.

Perform an audit of the model.

D.

Run red-teaming exercises.

Question 4

Retrieval-Augmented Generation (RAG) is defined as?

Options:

A.

Combining LLMs with private knowledge bases to improve their outputs.

B.

Reducing computational processing requirements of the LLMs.

C.

Applying advanced filtering techniques to the LLMs.

D.

Fine tuning LLMs to minimize biased outputs.

Question 5

Scenario:

An organization is building a compliance program to ensure responsible AI deployment. It aims to align operations with AI risk frameworks and mitigate legal, ethical, and operational risks, while still promoting innovation.

Which of the following would be theleast likelystep for an organization to take when designing an integrated compliance strategy for responsible AI?

Options:

A.

Meeting with and obtaining approval from senior management

B.

Launching a survey to understand the concerns and interests of potentially impacted stakeholders

C.

Consulting experts to consider the ethical principles underpinning the use of AI within the organization

D.

Employing a new software platform to modernize existing compliance processes across the organization

Question 6

All of the following analyses are part of a deactivating risk strategy EXCEPT?

Options:

A.

Understanding regulatory requirements related to data retention.

B.

Evaluating business continuity and financial risks.

C.

Understanding algorithmic methodology in AI model.

D.

Evaluating up and downstream system dependencies.

Question 7

An EU bank intends to launch a multi-modal Al platform for customer engagement and automated decision-making assist with the opening of bank accounts. The platform has been subject to thorough risk assessments and testing, where it proves to be effective in not discriminating against any individual on the basis of a protected class.

What additional obligations must the bank fulfill prior to deployment?

Options:

A.

The bank must obtain explicit consent from users under the privacy Directive.

B.

The bank must disclose how the Al system works under the Ell Digital Services Act.

C.

The bank must subject the Al system an adequacy decision and publish its appropriate safeguards.

D.

The bank must disclose the use of the Al system and implement suitable measures for users to contest automated decision-making.

Question 8

If it is possible to provide a rationale for a specific output of an Al system, that system can best be described as?

Options:

A.

Accountable.

B.

Transparent.

C.

Explainable.

D.

Reliable.

Question 9

Scenario:

A company is using different types of AI systems to enhance consumer engagement. These include chatbots, recommendation engines, and automated content generation tools.

Which of the following situations would beleast likelyto raise concerns under existing consumer protection laws?

Options:

A.

An AI algorithm being used in a credit decision-making process by a financial institution

B.

An AI customer service system claiming that it is as accurate as a human support agent

C.

An AI tool using scraped digital content to generate news summaries on a publishing website

D.

An online platform offering recommendations to its users by displaying user-specific content and targeted advertisements

Question 10

Scenario:

A distributor operating in the EU is responsible for selling imported high-risk AI systems to businesses. The distributor wants to ensure they fulfill all applicable obligations under the EU AI Act.

All of the following are obligations of a distributor of high-risk AI systems under the EU AI Act EXCEPT?

Options:

A.

Corrective actions

B.

Verification of CE marking

C.

Registration in EU Database

D.

Communication with national authorities

Question 11

Scenario:

A U.S.-based AI governance professional is evaluating resources from the National Institute of Standards and Technology (NIST) to guide the organization’s AI risk assessment strategy. They are particularly interested in programs focused on assessing AI-specific impacts.

The main purpose of NIST’sAssessing Risks and Impacts of AI (ARIA)program is to:

Options:

A.

Provide a suite of resources to manage risks

B.

Pilot new standards for AI red-teaming

C.

Promote interoperability across AI systems

D.

Offer a regulatory sandbox for risk reporting

Question 12

CASE STUDY

Please use the following answer the next question:

A mid-size US healthcare network has decided to develop an Al solution to detect a type of cancer that is most likely arise in adults. Specifically, the healthcare network intends to create a recognition algorithm that will perform an initial review of all imaging and then route records a radiologist for secondary review pursuant agreed-upon criteria (e.g., a confidence score below a threshold).

To date, the healthcare network has taken the following steps: defined its Al ethical principles: conducted discovery to identify the intended uses and success criteria for the system: established an Al governance committee; assembled a broad, crossfunctional team with clear roles and responsibilities; and created policies and procedures to document standards, workflows, timelines and risk thresholds during the project.

The healthcare network intends to retain a cloud provider to host the solution and a consulting firm to help develop the algorithm using the healthcare network ' s existing data and de-identified data that is licensed from a large US clinical research partner.

Which stakeholder group is most important in selecting the specific type of algorithm?

Options:

A.

The cloud provider.

B.

The consulting firm.

C.

The healthcare network ' sdata science team.

D.

The healthcare network ' s Al governance committee.

Question 13

CASE STUDY

A global marketing agency is adapting a large language model ( " LLM " ) to generate content for an upcoming marketing campaign for a client ' s new product: a hard hat designed for construction workers of any gender to better protect them from head injuries.

The marketing agency is accessing the LLM through an application programming interface ( " API " ) developed by a third-party technology company. They want to generate text to be used for targeted advertising communications that highlight the benefits of the hard hat to potential purchasers. Both the marketing agency and the technology company have taken reasonable steps to address Al governance.

The marketing company has:

•           Entered into a contract with the technology company with suitable representations and warranties.

•           Completed an impact assessment on the LLM for this intended use.

•           Built technical guidance on how to measure and mitigate bias in the LLM.

•           Enabled technical aspects of transparency, explainability, robustness and privacy.

•           Followed applicable regulatory requirements.

•           Created specific legal statements and disclosures regarding the use of the Al on its client ' s advertising.

The technology company has:

•           Provided guidance and resources to developers to address environmental concerns.

•           Build technical guidance on how to measure and mitigate bias in the LLM.

•           Provided tools and resources to measure bias specific to the LLM.

•           Enabled technical aspects of transparency, explainability, robustness and privacy.

•           Mapped and mitigated potential societal harms and large-scale impacts.

•           Followed applicable regulatory requirements and industry standards.

•           Created specific legal statements and disclosures regarding the LLM. including with respect to IP and rights to data.

The technology company has also addressed environmental concerns and societal harms.

Which of the following results would be considered biased outputs from this AI system EXCEPT?

Options:

A.

The generated ads are sent to construction companies, not individual workers

B.

The content generated for minority construction workers is insufficient

C.

The images of female workers are hyper-sexualized

D.

The advertising text generated for female audiences focuses on color and style

Question 14

A company is creating a mobile app to enable individuals to upload images and videos, and analyze this data using ML to provide lifestyle improvement recommendations. The signup form has the following data fields:

1.First name

2.Last name

3.Mobile number

4.Email ID

5.New password

6.Date of birth

7.Gender

In addition, the app obtains a device ' s IP address and location information while in use.

What GDPR privacy principles does this violate?

Options:

A.

Purpose Limitation and Data Minimization.

B.

Accountability and Lawfulness.

C.

Transparency and Accuracy.

D.

Integrity and Confidentiality.

Question 15

MULTI-SELECT

Please select 3 of the 5 options below. No partial credit will be given.

The use of paid generative AI public tools is appealing because?

Options:

A.

They are convenient to adopt.

B.

They have additional privacy and security controls.

C.

They have frequent enhancements of new features.

D.

They provide transparency in models and in decision-making.

E.

They eliminate concerns about the data used to generate outputs.

Question 16

Scenario:

A financial services company is planning a new AI project to assess creditworthiness. The AI team is mapping out what tasks should be completed during theplanning phaseof the AI lifecycle.

The planning phase of the AI lifecycle includes all of the following EXCEPT:

Options:

A.

Definition of underlying assumptions

B.

Approach to governance

C.

Choice of the architecture

D.

Context in which the model will operate

Question 17

A company that deploys AI but is not currently a provider or developer intends to develop and market its own AI system.

Which obligation would then be likely to apply?

Options:

A.

Implementing a risk management framework.

B.

Conducting an impact assessment including a post-deployment monitoring plan.

C.

Developing documentation on the system, the potential risks and the safeguards applied.

D.

Developing a reporting plan for any observed algorithmic discrimination or harms to individuals’ rights and freedoms.

Question 18

In the context of AI governance, what is the primary concern raised by the opacity of many AI systems?

Options:

A.

It ensures that AI systems will make decisions without any human involvement, increasing the risk of harmful outcomes.

B.

It prevents regulators from gaining legal access to the proprietary algorithms of private companies, limiting enforcement actions.

C.

It complicates efforts to trace and justify how specific outputs are generated, which can undermine accountability and informed oversight.

D.

It indicates that the system is inherently unreliable, meaning its predictions or recommendations cannot be trusted in practice.

Question 19

A bank is aiming to comply with ISO/IEC 42005:2025, and is studying how to adopt the standard in light of a new AI customer service system that it would like to implement.

In addition to the risk management process the bank already has in place to assess the risks of any potential new systems, which of the following actions is the most effective in adopting the ISO/IEC 42005:2025 standard?

Options:

A.

Collecting information on the AI system ' s performance to document additional AI risks.

B.

Adding AI risks to the risk register and continuing to leverage the existing risk management process.

C.

Defining a standalone AI impact assessment procedure to supplement the existing risk management process.

D.

Instructing AI developers to perform an AI impact assessment before development in addition to the existing risk management process.

Question 20

Scenario:

Business A provides grammar and writing assistance tools and licenses a generative AI model from Business B to enhance its offerings. Business A is concerned that the AI model might produce inappropriate or toxic content and wants to implement governance processes to prevent this.

Which of the following governance processes should Business A take tobest protect its usersagainst potentially inappropriate text?

Options:

A.

Business A should fine-tune the AI model on user-generated text that has been verified to be appropriate

B.

Business A should test that the AI model performs as expected and meets their minimum requirements for filtering toxic or obscene text

C.

Business A should establish a user reporting feature that allows users to flag toxic or obscene text, and report any incidents to Business B

D.

Business A should ask Business B for detailed documentation on the generative AI model ' s training data and whether it contained toxic or obscene sources

Question 21

Scenario:

An organization is developing a powerful general-purpose AI (GPAI) model that has systemic impact. The compliance team is assessing what legal obligations apply under the EU AI Act.

Under the EU AI Act, which of the following compliance actions appliesonly to General Purpose AI models with systemic risk?

Options:

A.

Publishing a detailed summary of the data used to train the model

B.

Maintaining up-to-date technical documentation, including testing details

C.

Implementing an intellectual property policy to comply with EU copyright laws

D.

Making information available to downstream providers who integrate the model into their AI systems

Question 22

Who is responsible for ongoing maintenance and monitoring of an AI system after it has been put into production?

Options:

A.

Regulator.

B.

Developer.

C.

Deployer.

D.

User.

Question 23

All of the following types of testing can help evaluate the performance of a responsible Al system EXCEPT?

Options:

A.

Risk probability/severity.

B.

Adversarial robustness.

C.

Statistical sampling.

D.

Decision analysis.

Question 24

When should an ethical impact assessment for AI be performed?

Options:

A.

When the system is ready for production and deployment.

B.

When the number of AI system users has reached a predefined threshold.

C.

After the AI system has encountered ethical issues in real-world applications.

D.

At the initial stages of AI system development and continually throughout its lifecycle.

Question 25

Decreasing the complexity of a machine learning model reduces variance and?

Options:

A.

Increases bias.

B.

Increases accuracy.

C.

Decreases tolerance.

D.

Decreases interpretability.

Question 26

CASE STUDY

Please use the following to answer the next question:

A mid-size US healthcare network has decided to develop an AI solution to detect a type of cancer that is most likely to arise in adults. Specifically, the healthcare network intends to create a recognition algorithm that will perform an initial review of all imaging and then route records to a radiologist for secondary review pursuant to agreed-upon criteria such as a confidence score below a threshold.

To date, the healthcare network has:

Defined its AI ethical principles

Conducted discovery to identify the intended uses and success criteria for the system

Established an AI risk committee

Assembled a cross-functional team with clear roles and responsibilities

Created policies and procedures to document standards, workflows, timelines and risk thresholds during the project

The healthcare network intends to retain a cloud provider to host the solution. It also intends to retain a large consulting firm to supplement its small data science team and help develop the algorithm using the healthcare network ' s existing data and de-identified data that is licensed from a large US clinical research partner.

Which of the following steps can best mitigate the possibility of discrimination prior to training and testing the AI solution?

Options:

A.

Procure more data from clinical research partners.

B.

Engage a third party to perform an audit.

C.

Perform an impact assessment.

D.

Create a bias bounty program.

Question 27

The OECD ' s Ethical Al Governance Framework is a self-regulation model that proposes to prevent societal harms by?

Options:

A.

Establishing explain ability criteria to responsibly source and use data to train Al systems.

B.

Defining requirements specific to each industry sector and high-risk Al domain.

C.

Focusing on Al technical design and post-deployment monitoring.

D.

Balancing Al innovation with ethical considerations.

Question 28

CASE STUDY

A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.

The data processed by the AI system would be classified as:

Options:

A.

Non-sensitive personal data, since it does not reveal information about health, gender or race

B.

Organizational data, since it is part of the authentication process

C.

Non-personal data, as long as it is not linked to a user ID

D.

Special category data, if it can be used to uniquely identify a person

Question 29

You are an engineer that developed an AI-based ad recommendation tool.

Which of the following should be monitored to evaluate the tool ' s effectiveness?

Options:

A.

Output data, to assess the delta between the prediction and actual ad clicks.

B.

Algorithmic patterns, to show the model has a high degree of accuracy.

C.

Input data, to ensure the ads are reaching the target audience.

D.

GPU performance, to evaluate the tool ' s robustness.

Question 30

A US-based mortgage lender has purchased a chatbot. They plan to have the chatbot collect information from consumers who are interested in loans and offer the consumers 2-3 different options based on its current pricing and product offerings, which change frequently. This chatbot was initially developed and previously deployed by a Russian airline for booking flights.

The best option for the part of the process that generates the loan offers is?

Options:

A.

Retrieval-Augmented Generation.

B.

Multimodal Generative AI.

C.

Expert System.

D.

Quantum computing

Question 31

What is a key opportunity for companies deploying proprietary Agentic AI models?

Options:

A.

Increased immunity from intellectual property claims.

B.

Transferring risk to the cloud vendor.

C.

Greater ability to customize guardrails.

D.

Reduced need for internal AI governance.

Question 32

After initially deploying a third-party AI model, you learn the developer has released a new version.

As deployer of this third-party model, what should you do?

Options:

A.

Audit the model.

B.

Retrain the model.

C.

Seek input from data scientists.

D.

Communicate necessary updates to your users.

Question 33

A company is working to develop a self-driving car that can independently decide the appropriate route to take the driver after the driver provides an address.

If they want to make this self-driving car “strong” Al, as opposed to " weak,” the engineers would also need to ensure?

Options:

A.

That the Al has full human cognitive abilities that can independently decide where to take the driver.

B.

That they have obtained appropriate intellectual property (IP) licenses to use data for training the Al.

C.

That the Al has strong cybersecurity to prevent malicious actors from taking control of the car.

D.

That the Al can differentiate among ethnic backgrounds of pedestrians.

Question 34

CASE STUDY

Please use the following answer the next question:

A mid-size US healthcare network has decided to develop an Al solution to detect a type of cancer that is most likely arise in adults. Specifically, the healthcare network intends to create a recognition algorithm that will perform an initial review of all imaging and then route records a radiologist for secondary review pursuant agreed-upon criteria (e.g., a confidence score below a threshold).

To date, the healthcare network has taken the following steps: defined its Al ethical principles: conducted discovery to identify the intended uses and success criteria for the system: established an Al governance committee; assembled a broad, crossfunctional team with clear roles and responsibilities; and created policies and procedures to document standards, workflows, timelines and risk thresholds during the project.

The healthcare network intends to retain a cloud provider to host the solution and a consulting firm to help develop the algorithm using the healthcare network ' s existing data and de-identified data that is licensed from a large US clinical research partner.

In the design phase, what is the most important step for the healthcare network to take when mapping its existing data to the clinical research partner data?

Options:

A.

Apply privacy-enhancing technologies to the data.

B.

Identify fits and gaps in the combined data.

C.

Ensure the data is labeled and formatted.

D.

Evaluate the country of origin of the data.

Question 35

Please select 3 of the 5 options below. No partial credit will be given.

All of the following are unique characteristics of AI that require a comprehensive approach to governance EXCEPT?

Options:

A.

Autonomy.

B.

Automation.

C.

Adaptability.

D.

Speed and scale.

E.

Superintelligence.

Question 36

Which stakeholder is responsible for lawful collection of data for the training of the foundational AI model?

Options:

A.

The marketing agency.

B.

The tech company.

C.

The data aggregator.

D.

The marketing agency ' s client.

Question 37

The most important factor in ensuring fairness when training an Al system is?

Options:

A.

The architecture and model selection.

B.

The data labeling and classification.

C.

The data attributes and variability.

D.

The model accuracy and scale.

Question 38

An AI start-up is developing a system for automated loan approvals. The team wants to minimize risks of bias and regulatory non-compliance. They have already identified potential stakeholders, including regulators and consumer groups.

What is the most appropriate sequence of next steps?

Options:

A.

Conduct harm analysis,

Benchmark system performance,

Proceed to deployment if the system performs similarly.

B.

Launch a small-scale pilot,

Gather user feedback,

Afterward analyze harms.

C.

Perform a probability/severity analysis,

Apply a risk mitigation hierarchy to address the most severe risks,

Conduct pre-deployment pilot testing.

D.

Enable explainability tools to reassure users,

Launch pilot,

Map risks during deployment.

Question 39

Which of the following use cases would be best served by a non-AI solution?

Options:

A.

A non-profit wants to develop a social media presence.OB. An e-commerce provider wants to make personalized recommendations.

B.

A business analyst wants to forecast future cost overruns and underruns.

C.

A customer service agency wants automate answers to common questions.

Question 40

An artist has been using an Al tool to create digital art and would like to ensure that it has copyright protection in the United States.

Which of the following is most likely to enable the artist to receive copyright protection?

Options:

A.

Ensure the tool was trained using publicly available content.

B.

Obtain a representation from the Al provider on how the tool works.

C.

Provide a log of the prompts the artist used to generate the images.

D.

Update the images in a creative way to demonstrate that it is the artist ' s.

Question 41

CASE STUDY

Please use the following answer the next question:

A local police department in the United States procured an Al system to monitor and analyze social media feeds, online marketplaces and other sources of public information to detect evidence of illegal activities (e.g., sale of drugs or stolen goods). The Al system works by surveilling the public sites in order to identify individuals that are likely to have committed a crime. It cross-references the individuals against data maintained by law enforcement and then assigns a percentage score of the likelihood of criminal activity based on certain factors like previous criminal history, location, time, race and gender.

The police department retained a third-party consultant assist in the procurement process, specifically to evaluate two finalists. Each of the vendors provided information about their system ' s accuracy rates, the diversity of their training data and how their system works. The consultant determined that the first vendor’s system has a higher accuracy rate and based on this information, recommended this vendor to the police department.

The police department chose the first vendor and implemented its Al system. As part of the implementation, the department and consultant created a usage policy for the system, which includes training police officers on how the system works and how to incorporate it into their investigation process.

The police department has now been using the Al system for a year. An internal review has found that every time the system scored a likelihood of criminal activity at or above 90%, the police investigation subsequently confirmed that the individual had, in fact, committed a crime. Based on these results, the police department wants to forego investigations for cases where the Al system gives a score of at least 90% and proceed directly with an arrest.

Which Al risk would NOT have been identified during the procurement process based on the categories of information requested by the third-party consultant?

Options:

A.

Security.

B.

Accuracy.

C.

Explainability.

D.

Discrimination.

Question 42

Pursuant to the White House Executive Order of November 2023, who is responsible for creating guidelines to conduct red-teaming tests of Al systems?

Options:

A.

National Institute of Standards and Technology (NIST).

B.

National Science and Technology Council (NSTC).

C.

Office of Science and Technology Policy (OSTP).

D.

Department of Homeland Security (DHS).

Question 43

CASE STUDY

A global marketing agency is adapting a large language model ( " LLM " ) to generate content for an upcoming marketing campaign for a client ' s new product: a hard hat designed for construction workers of any gender to better protect them from head injuries.

The marketing agency is accessing the LLM through an application programming interface ( " API " ) developed by a third-party technology company. They want to generate text to be used for targeted advertising communications that highlight the benefits of the hard hat to potential purchasers. Both the marketing agency and the technology company have taken reasonable steps to address Al governance.

The marketing company has:

•           Entered into a contract with the technology company with suitable representations and warranties.

•           Completed an impact assessment on the LLM for this intended use.

•           Built technical guidance on how to measure and mitigate bias in the LLM.

•           Enabled technical aspects of transparency, explainability, robustness and privacy.

•           Followed applicable regulatory requirements.

•           Created specific legal statements and disclosures regarding the use of the Al on its client ' s advertising.

The technology company has:

•           Provided guidance and resources to developers to address environmental concerns.

•           Build technical guidance on how to measure and mitigate bias in the LLM.

•           Provided tools and resources to measure bias specific to the LLM.

•           Enabled technical aspects of transparency, explainability, robustness and privacy.

•           Mapped and mitigated potential societal harms and large-scale impacts.

•           Followed applicable regulatory requirements and industry standards.

•           Created specific legal statements and disclosures regarding the LLM. including with respect to IP and rights to data.

The marketing company and its tech provider have taken reasonable steps to govern the AI’s use, including legal disclosures, impact assessments, and bias mitigation. However, the company wants to takeone more stepto improve governance and reduce risks related to ongoing oversight and accountability.

While the marketing agency took steps to mitigate its risks, the best additional step would be to:

Options:

A.

Negotiate an intellectual property indemnity from the technology company

B.

Evaluate the use of AI in the marketing industry to identify best practices

C.

Engage a third party to lead the procurement selection process

D.

Establish a governance committee to oversee the project

Question 44

CASE STUDY

Please use the following answer the next question:

A local police department in the United States procured an Al system to monitor and analyze social media feeds, online marketplaces and other sources of public information to detect evidence of illegal activities (e.g., sale of drugs or stolen goods). The Al system works by surveilling the publicsites in order to identify individuals that are likely to have committed a crime. It cross-references the individuals against data maintained by law enforcement and then assigns a percentage score of the likelihood of criminal activity based on certain factors like previous criminal history, location, time, race and gender.

The police department retained a third-party consultant assist in the procurement process, specifically to evaluate two finalists. Each of the vendors provided information about their system ' s accuracy rates, the diversity of their training data and how their system works. The consultant determined that the first vendor’s system has a higher accuracy rate and based on this information, recommended this vendor to the police department.

The police department chose the first vendor and implemented its Al system. As part of the implementation, the department and consultant created a usage policy for the system, which includes training police officers on how the system works and how to incorporate it into their investigation process.

The police department has now been using the Al system for a year. An internal review has found that every time the system scored a likelihood of criminal activity at or above 90%, the police investigation subsequently confirmed that the individual had, in fact, committed a crime. Based on these results, the police department wants to forego investigations for cases where the Al system gives a score of at least 90% and proceed directly with an arrest.

When notifying an accused perpetrator, what additional information should a police officer provide about the use of the Al system?

Options:

A.

Information about the accuracy of the Al system.

B.

Information about how the accused can oppose the charges.

C.

Information about the composition of the training data of the system.

D.

Information about how the individual was identified by the Al system.

Question 45

CASE STUDY

Please use the following answer the next question:

ABC Corp, is a leading insurance provider offering a range of coverage options to individuals. ABC has decided to utilize artificial intelligence to streamline and improve its customer acquisition and underwriting process, including the accuracy and efficiency of pricing policies.

ABC has engaged a cloud provider to utilize and fine-tune its pre-trained, general purpose large language model (“LLM”). In particular, ABC intends to use its historical customer data—including applications, policies, and claims—and proprietary pricing and risk strategies to provide an initial qualification assessment of potential customers, which would then be routed tA. human underwriter for final review.

ABC and the cloud provider have completed training and testing the LLM, performed a readiness assessment, and made the decision to deploy the LLM into production. ABC has designated an internal compliance team to monitor the model during the first month, specifically to evaluate the accuracy, fairness, and reliability of its output. After the first month in production, ABC realizes that the LLM declines a higher percentage of women ' s loan applications due primarily to women historically receiving lower salaries than men.

The best approach to enable a customer who wants information on the Al model ' s parameters for underwriting purposes is to provide?

Options:

A.

A transparency notice.

B.

An opt-out mechanism.

C.

Detailed terms of service.

D.

Customer service support.

Question 46

MULTI-SELECT

Please select 3 of the 5 options below. No partial credit will be given.

Which of the following best describes data dependency with regard to an AI model?

Options:

A.

An AI model ' s performance depends on the quality, quantity, and diversity of its training data.

B.

Using privacy-enhancing techniques is a core principle of data dependency in AI models.

C.

Having large, high-quality datasets reduces data dependency in AI models.

D.

The complexity and architecture of an AI model are influenced by the characteristics of its training data.

E.

Biases and limitations in an AI model often originate from biases and limitations present in its training data.

Question 47

CASE STUDY

Please use the following answer the next question:

XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company ' s product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team ' s goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization ' s operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

All of the following are potential negative consequences created by using the Al tool when making hiring decisions EXCEPT?

Options:

A.

Reputational harm.

B.

Civil rights violations.

C.

Discriminatory treatment.

D.

Intellectual property infringement.

Question 48

Business A sells software that provides users with writing and grammar assistance. Business B is a cloud services provider that trains its own AI models.

* Business A has decided to add generative AI features to their software.

* Rather than create their own generative AI model, Business A has chosen to license a model from Business B.

* Business A will then integrate the model into their writing assistance software to provide generative AI capabilities.

* Business A is most concerned that its writing assistance software could recommend toxic or obscene text to its users.

Which of the following governance processes should Business A take to best protect its users against potentially inappropriate text?

Options:

A.

Business A should fine-tune the AI model on user-generated text that has been verified to be appropriate.

B.

Business A should test that the AI model performs as expected and meets their minimum requirements for filtering toxic or obscene text.

C.

Business A should establish a user reporting feature that allows users to flag toxic or obscene text, and report any incidents to Business B.

D.

Business A should ask Business B for detailed documentation on the generative AI model ' s training data and whether it contained toxic or obscene sources.

Question 49

MULTI-SELECT

Please select 3 of the 5 options below. No partial credit will be given.

Training an AI model is time-consuming because of?

Options:

A.

The complexity of the AI model.

B.

The maturity of AI governance.

C.

The volume of training data.

D.

The number of stakeholders.

E.

The quality of the training data.

Question 50

CASE STUDY

A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.

All of the following are obligations of the company as a data controller when implementing its AI system EXCEPT?

Options:

A.

Ensuring that third-party processors are based in the same country as the company

B.

Allowing data subject access requests (DSARs)

C.

Implementing technical and organizational measures

D.

Conducting a Data Protection Impact Assessment (DPIA) / Privacy Impact Assessment (PIA)

Question 51

A company ' s AI-powered hiring tool is found to be consistently ranking male candidates higher than female candidates with similar qualifications.

Which of the following is the most immediate and critical governance action required to address this issue?

Options:

A.

Log the incident in the company ' s central AI incident management system.

B.

Conduct a comprehensive audit of the AI system ' s entire lifecycle.

C.

Notify cross-functional stakeholders.

D.

Initiate a full-scale retraining of the AI model with a more balanced dataset.

Question 52

According to the GDPR ' s transparency principle, when an Al system processes personal data in automated decision-making, controllers are required to provide data subjects specific information on?

Options:

A.

The existence of automated decision-making and meaningful information on its logic and consequences.

B.

The personal data used during processing, including inferences drawn by the Al system about the data.

C.

The data protection impact assessments carried out on the Al system and legal bases for processing.

D.

The contact details of the data protection officer and the data protection national authority.

Question 53

CASE STUDY

Please use the following answer the next question:

Good Values Corporation (GVC) is a U.S. educational services provider that employs teachers to create and deliver enrichment courses for high school students. GVC has learned that many of its teacher employees are using generative Al to create the enrichment courses, and that many of the students are using generative Al to complete their assignments.

In particular, GVC has learned that the teachers they employ used open source large language models (“LLM”) to develop an online tool that customizes study questions for individual students. GVC has also discovered that an art teacher has expressly incorporated the use of generative Al into the curriculum to enable students to use prompts to create digital art.

GVC has started to investigate these practices and develop a process to monitor any use of generative Al, including by teachers and students, going forward.

All of the following may be copyright risks from teachers using generative Al to create course content EXCEPT?

Options:

A.

Content created by an LLM may be protectable under U.S. intellectual property law.

B.

Generative Al is generally trained using intellectual property owned by third parties.

C.

Students must expressly consent to this use of generative Al.

D.

Generative Al often creates content without attribution.

Question 54

The framework set forth in the White House Blueprint for an Al Bill of Rights addresses all of the following EXCEPT?

Options:

A.

Human alternatives, consideration and fallback.

B.

High-risk mitigation standards.

C.

Safe and effective systems.

D.

Data privacy.

Question 55

Scenario:

A company using AI for resume screening understands the risks of algorithmic bias and the evolving legal requirements across jurisdictions. It wants to implement the right governance controls to prevent reputational damage from misuse of the AI hiring tool.

Which of the following measures should the company adopt to best mitigate its risk of reputational harm from using the AI tool?

Options:

A.

Test the AI tool pre- and post-deployment

B.

Ensure the vendor provides indemnification for the AI tool

C.

Require the procurement and deployment teams to agree upon the AI tool

D.

Continue to require the company’s hiring personnel to manually screen all applicants

Question 56

According to the GDPR, an individual has the right to have a human confirm or replace an automated decision unless that automated decision?

Options:

A.

Is authorized with the data subject s explicit consent.

B.

Is authorized by applicable Ell law and includes suitable safeguards.

C.

Is deemed to solely benefit the individual and includes documented legitimate interests.

D.

Is necessary for entering into or performing under a contract between the data subject and data controller.

Question 57

All of the following are potential benefits of using private over public LLMs EXCEPT?

Options:

A.

Reduction in time taken for data validation and verification.

B.

Confirmation of security and confidentiality.

C.

Reduction in possibility of hallucinated information.

D.

Application for specific use cases within the enterprise.

Question 58

Which of the following is NOT a common type of machine learning?

Options:

A.

Deep learning.

B.

Cognitive learning.

C.

Unsupervised learning.

D.

Reinforcement learning.

Question 59

To maintain fairness in a deployed system, it is most important to?

Options:

A.

Protect against loss of personal data in the model.

B.

Monitor for data drift that may affect performance and accuracy.

C.

Detect anomalies outside established metrics that require new training data.

D.

Optimize computational resources and data to ensure efficiency and scalability.

Question 60

Why is it important that conformity requirements are satisfied before an AI system is released into production?

Options:

A.

To ensure the visual design is fit for purpose.

B.

To ensure the AI system is easy for end-users to operate.

C.

To guarantee interoperability of the AI system across multiple platforms and environments.

D.

To comply with legal and regulatory standards, ensuring the AI system is safe and trustworthy.

Question 61

A shipping service based in the US is looking to expand its operations into the EU. It utilizes an in-house developed multimodal AI model that analyzes all personal data collected from shipping senders and recipients, and optimizes shipping routes and schedules based on this data.

As they expand into the EU, all of the following descriptions should be included in the technical documentation for their AI model EXCEPT?

Options:

A.

A general description of the AI system.

B.

A description of the prioritization of the risks of deployment of the AI system.

C.

A description of the appropriateness of the performance metrics for the specific AI system.

D.

A detailed description of the elements of the AI system and of the process for its development.

Question 62

All of the following are elements of establishing a global Al governance infrastructure EXCEPT?

Options:

A.

Providing training to foster a culture that promotes ethical behavior.

B.

Creating policies and procedures to manage third-partyrisk.

C.

Understanding differences in norms across countries.

D.

Publicly disclosing ethical principles.

Question 63

In procuring an AI system from a vendor, which of the following would be important to include in a contract to enable proper oversight and auditing of the system?

Options:

A.

Liability for mistakes.

B.

Ownership of data and outputs.

C.

Responsibility for improvements.

D.

Appropriate access to data and models.

Question 64

Which of the following elements of feature engineering is most important to mitigate the potential bias in an Al system?

Options:

A.

Feature selection.

B.

Feature validation.

C.

Feature transformation.

D.

Feature importance analysis.

Page: 1 / 22
Total 215 questions